Configure Splunk SOAR apps in Splunk Enterprise Security
Apps expand the capabilities of Splunk Enterprise Security by connecting to third-party products and services. These third-party products and services provide actions you can use to run or automate playbooks. For example, you can use the get email action from the Microsoft 365 email app in your playbooks.
You can configure apps in the following places:
-
Use the Connector Builder Agent in Splunk Enterprise Security
Notes about configuring apps in Splunk Enterprise Security when paired with Splunk SOAR:
-
All apps in SOAR are listed in Enterprise Security.
-
Not all available apps support data ingestion for use in Enterprise Security.
-
Splunk SOAR is the source of data used by the apps, regardless of where the data is used.
-
You can configure most apps in either SOAR or Enterprise Security, however, you must configure apps that ingest data in the location where the data will be used:
-
If an app will use SOAR data only within SOAR, configure that app in SOAR.
-
If an app will ingest SOAR data for use in Enterprise Security, configure that app in Enterprise Security.
-
Within Splunk SOAR, the term asset is used in addition to the term app. An asset is a specific configuration, or instance, of an app. An asset is configured with the information required to communicate with the third-party product or service, such as IP address, automation service account, username, and password.
Create and edit connectors with the Connector Builder Agent
use agentic AI to build connectors
Use the Splunk Connector Builder Agent to build and test new connectors, modify existing connectors, and to help you configure existing connectors.
Before you begin
Splunk Connector Builder Agent has the following requirements:
-
Must use Splunk Platform version 10.1.x or higher
-
Splunk SOAR (Cloud) must be paired with Splunk Enterprise Security version 8.7.0 or higher. For pairing details, see the following documentation and consult your Splunk administrator:
-
From the Splunk SOAR side: Pair Splunk SOAR (Cloud) with Splunk Enterprise Security
-
From the Splunk Enterprise Security side: Pair Splunk Enterprise Security with Splunk SOAR
-
-
To use the Connector Builder Agent, users must have the following permissions. For details, see Manage roles and permissions in Splunk SOAR (Cloud).
-
SOAR App: Edit
-
SOAR Asset: Edit
-
Access the Connector Builder Agent
The Connector Builder Agent is part of the Splunk Enterprise Security Apps page.
Here are some examples for how you might use the Connector Builder Agent:
-
Build and test a new connector for your organization's needs. For example, you can create a new connector to interface with a custom app you created and use in your organization. This app must have a REST API.
-
Modify and test an existing Splunk-provided app. For example, you might want to modify the authentication or add or modify an action.
-
Ask for help with configuring a connector. For example, you might want more information on how to configure a specific field.
-
Obtain help with testing a connector. For example, if you received an error message while testing an app, you can ask the Agent for help fixing that error.
Build and test a new connector
Use the Connector Builder Agent to build a new connector to suit your organization's needs. Then use the Connector Builder Agent to test the connectors.
In this section, we'll use an example of creating a new connector to interface with a custom security tool used in your organization.
To build a new connector, follow these steps:
-
Open the Connector Builder Agent in the Apps page. Select Configure, then Splunk SOAR, then Apps. If the chat panel is not visible, select the AI sparkle icon in the margin.
-
Select one of the provided prompts, like Build a new connector or enter your own. For example, you might enter Build a new connector for my custom app called MyCustomSecurityApp.
The agent requests information and provides an example format.
-
Locate the required information. Copy it and paste it into the agent chat window. The Connector Builder Agent works with the details you provide.
General information required usually includes:
- API, written in one of the following formats:
- OpenAPI/Swagger
- Postman collection
- Endpoint table
- Plain-English description
- Base URL
- Authentication method
- Endpoints/actions to support
- Request/response examples, if available
- API, written in one of the following formats:
-
Prompt the agent, iterating as needed to refine any details.
-
When you are satisfied with the connector and it has been built successfully, provide your approval for the agent to deploy the connector to your Splunk SOAR instance.
-
When you have completed building the connector, search for the connector in the App list.
-
Select Configure to configure your new connector. Provide your approval to perform the configuration.
-
Configure your connector as you would any other connector. For details on configuration values and how to test your connector, see
Configure apps in Splunk Enterprise Security. -
After you have configured your connector, prompt the agent to test the actions you created.
-
If testing results in errors or if you have questions, ask the Connector Builder Agent for help with error messages or other testing questions.
Build and test a connector for an existing app
Use the Connector Builder Agent to create a new connector or update an existing connector for an existing SOAR SDK-based app to suit your organization's needs. Then use the Connector Builder Agent to test the connector.
To build a new connector for an existing app, follow these steps:
-
Open the Connector Builder Agent in the Apps page. Select Configure, then Splunk SOAR, then Apps. If the chat panel is not visible, select the AI sparkle icon in the margin.
-
Select one of the provided prompts, like Update an existing connector or enter your own. For example, you might enter Add a new connector for the VirusTotal app.
The agent might request additional information, like the app number for the app.
-
If you are updating an existing connector, the Agent requests that you clone the app so you can edit the connector.
-
Locate the documentation for the app in the App list. Copy it and paste it into the agent chat window. The Connector Builder Agent works with the details you provide.
-
Prompt the agent about the new connector you want to create, iterating as needed to refine any details.
-
When you are satisfied with the connector and it has been built successfully, provide your approval for the agent to deploy the connector to your Splunk SOAR instance.
-
When you have completed building the connector, search for the connector in the App list.
-
Select Configure to configure your new connector.
Configure your connector as you would any other connector. For details on configuration values and how to test your connector, see
Configure apps in Splunk Enterprise Security. -
After you have configured your connector, prompt the agent to test the actions you created.
-
If testing results in errors or if you have questions, ask the Connector Builder Agent for help with error messages or other testing questions.
Help configuring a connector
If you have questions while configuring an existing connector, the Connector Builder Agent can provide information. In the asset configuration screen, ask the Connector Builder Agent for information. For example, while you are configuring the Microsoft 365 app, you might ask something like What is a tenant ID? or Where do I find the Certificate Thumbprint?. You can then use responses from the agent to complete the configuration.
Interact with the Connector Builder Agent
-
To start a chat with the Connector Builder Agent, select the circle sparkle icon
.
-
In the prompt field, ask a question or select one of the suggested prompts. Continue to use the same chat to ask related questions and refine your prompt.
Review the suggestions carefully. When ready, accept the suggestions in the chat.
-
To start a new chat, abandoning your current thread, select the new chat icon
.
-
Copy or download the agent response to use or save it somewhere else. Select the copy
or download
icon.
-
Provide feedback to the agent's response by selecting the thumbs up or thumbs down icon within the chat panel.
See also
For additional details on apps and connectors, review these articles:
- Configure apps in Splunk Enterprise Security in this guide
- Add and configure apps and assets to provide actions in Splunk SOAR (Cloud) in the Splunk SOAR (Cloud) documentation
Configure apps in Splunk Enterprise Security
set up apps directly within Enterprise Security
To view and configure apps within Splunk Enterprise security, from the Configure menu, select Splunk SOAR, then Apps.
The Apps page displays installed apps in two tabs: Configured and Not configured. Each app includes a brief description, along with labels that show its attributes. Most labels describe the specific actions of the app, like lookup ip and get threat details. To filter by action category, like firewall, email, or reputation, use the Select filters menu when searching.
To find apps that can ingest data to use within Splunk Enterprise security, look for the Support ES Ingestion category and on es poll label. You can configure these apps completely within Enterprise Security, including ingestion settings, like how often you want the app to poll to ingest data.
You must use Enterprise Security to configure ingestion information for apps within Enterprise Security; you cannot configure that information within Splunk SOAR.
Apps configured in Enterprise Security must have the on es poll label to be able to poll for Enterprise Security data.
View and configure apps
To view and configure apps that are not yet configured, or to update apps that have already been configured, follow these steps:
From the Configure menu, select Splunk SOAR, then Apps. Select the Not configured tab to configure newer apps or the Configured tab to update configuration for previously configured apps.
-
Locate the app you want to set up and select Configure.
Note: A message displays, warning that the installation of this app is not yet complete. Following these steps will complete the app configuration. -
Enter a unique name for the app. Note that you cannot change the name after you save the app.
-
Complete the app's required fields, indicated with asterisks (*). Required fields differ for each app. Read the documentation for the app in the side panel. This documentation is provided by the app developer, not necessarily by Splunk.
-
(Optional) Complete additional fields for this app.
-
(Optional) Complete some or all of the Advanced configuration settings. This section of the documentation contains essential, but abbreviated information. For complete details, refer to Configure advanced settings in Administer Splunk SOAR (Cloud) or Configure advanced settings in Administer Splunk SOAR (On-premises).
Note: Some fields specific to configuration for Splunk SOAR ingestion do not appear when configuring an app in Splunk Enterprise Security. This is expected.Advanced setting field Description Concurrent action limit Controls how many actions this asset can run simultaneously. Increasing this limit can improve performance. If left blank, default value is 50. Enable just in time credentials Select one or more fields that will require a user to enter credentials before action is taken. This setting is often used by organizations with policies against providing credentials automatically.
If you specify one or more settings in this field, you can no longer use ingestion (use Automation Broker) for this app.
User for automated actions The account to use for automated actions, like testing connectivity. This user appears in log files. The automationuser is often specified for this duty. -
Optionally enter environmental variables to apply variables for this app. Note that global environment variables take precedence over any configured in an asset. This section of the documentation contains essential, but abbreviated information. For complete details, refer to Set global environment variables in Administer Splunk SOAR (Cloud) or Set global environment variables in Administer Splunk SOAR (On-premises).
Specify the relevant type of proxy for the name: HTTP_PROXY, HTTPS_PROXY, or NO_PROXY (case-sensitive) ,then provide a value. Select Secret to encrypt and hide the value.
-
Select Save or select Next to continue with Ingest settings.
Ingest setting configuration
-
For each app using Enterprise Security data, make a selection for each of the following required fields.
Investigation type Options include phishing or ransomware. Investigation types specified in Configurations > Findings and investigations > Investigation types Security domain Options are access, endpoint, network, threat, identity, and audit. These options are defined by Enterprise Security and cannot be customized. Urgency Options are critical, high, medium, low, and informational. These options are defined by Enterprise Security and cannot be customized. -
Specify information to configure drill-down dashboards, where you can visualize the drill-down searches. For complete details, see Configure drill-down dashboards for a finding.
Note: To configure or edit drill-down dashboards, you must have the capability to view the specific dashboard and edit detections. To view the drill-down dashboard from the Mission Control page, you must have viewing permissions for the specific dashboard.Field Description Dashboard Select an existing Splunk dashboard in your Enterprise Security deployment that you want to use for these findings. Name Specify a name you want to associate with these findings on the analyst queue. Supports tokens (see next row). Tokens Optionally add one or more tokens to use to filter these findings in the dashboard. For details on tokens, in addition to the link above this table, seeManage analyst workflows using the analyst queue in Splunk Enterprise Security -
Specify information to configure drill-down dashboards, where you can visualize the drill-down searches. For complete details, see Configure drill-down dashboards for a finding.
Note: To configure or edit drill-down dashboards, you must have the capability to view the specific dashboard and edit detections. To view the drill-down dashboard from the Mission Control page, you must have viewing permissions for the specific dashboard.Field Description Dashboard Select an existing Splunk dashboard in your Enterprise Security deployment that you want to use for these findings. Name Specify a name you want to associate with these findings on the analyst queue. Supports tokens (see next row). Tokens Optionally add one or more tokens to use to filter these findings in the dashboard. For details on tokens, in addition to the link above this table, see Manage analyst workflows using the analyst queue in Splunk Enterprise Security. Tokens are case-sensitive. - By default, the following options for threat analysis are selected. Clear the checkboxes if you do not want to perform these actions automatically.
-
Run threat analysis: Perform threat analysis on finding attachments after findings are created. For example, you can analyze an email attached to a finding.
-
Launch automation after threat analysis is complete: Run the automation rule associated with this asset, after running the threat analysis. For details on automation rules, see Configure automation rules to run playbooks based on findings in Splunk Enterprise Security.
-
-
Select Save or select Next to continue with Custom Settings.
Custom Settings configuration
Different apps have different configuration requirements. Not all settings are required, or present, for each app.
-
Automation Broker: Specify the automation broker to use to poll for ingesting data. For details on automation brokers, see About Splunk SOAR Automation Broker.
-
Access control settings:
-
For security and by default, granular asset permissions are turned on, so only a specific list of users and roles can access apps and assets. To change this permission, select the link.
-
Select which actions you want the app to take. To take all actions, select the star (asterisk).
-
Specify which users and roles can access this app.
-
- Approval settings
-
Optionally specify users, roles, or both to function as primary and secondary approvers. Specify the number of primary and secondary approvers from the users and roles you selected.
-
-
Select Save or select Next to continue with Additional Settings.
Additional Settings
Different apps have different configuration requirements. Not all settings are required, or present, for each app.
-
Enter a description for this app.
-
Select tags from Splunk SOAR so this app will be easier to find, flag objects, and use in playbooks. For details on SOAR tags, including roles required to view and edit tags, see the following documentation for your deployment type:
-
Add tags to objects in Splunk SOAR (Cloud) in Administer Splunk SOAR (Cloud)
-
Add tags to objects in Splunk SOAR (On-premises) in Administer Splunk SOAR (On-premises)
-
-
Select Save to complete the configuration for this app.
The app displays with all of the configurations you specified.
-
If the app supports it, a Test Connectivity button appears. Select the button to check that the app works with the configuration you specified. Read the messages displayed to learn how to fix any connectivity issues with your app. Update the connectivity configuration, then test again.
Clone an app between SOAR and Enterprise Security
Save time by creating and editing a copy of an app used in SOAR, rather than starting from scratch
If you have an app that is configured to ingest data from, and use that data within, Splunk SOAR, you can clone that app to use that ingested data within Splunk Enterprise Security. Cloning an app saves time, because almost all of the configuration information is copied; you only need to configure the ingestion settings.
To clone an app, follow these steps:
-
In Enterprise Security, from the Configure menu, select Splunk SOAR, then Apps.
-
Select the Configured tab. Browse or search for an app you want to use to use ingested data within Splunk Enterprise Security.
-
Select View to view the app's configuration, then select Ingest Settings.
-
At the start of the Ingest Settings section, a note appears, letting you know that you can clone the asset. Select the Clone this asset link. A new settings screen appears where you can specify configuration settings.
-
Provide a name to distinguish this new asset from the SOAR-focused asset.
-
Provide Enterprise Security ingestion information.
-
Optionally update other configuration settings that were cloned from the SOAR-focused asset.
-
Select Save.
Add and configure apps and assets in Splunk SOAR
how to add and configure apps when you cannot do so in Splunk Enterprise Secuirty
For apps not yet configurable within Splunk Enterprise Security, you can add or configure them in Splunk SOAR. At the top of the Apps page, select Add apps in SOAR.
For details on creating and configuring apps and assets in Splunk SOAR, refer to the documentation in the next section, See also.
After you configure an app in Splunk SOAR, it appears in the list of apps you can configure in Splunk Enterprise Security. For details, see Configure Splunk SOAR apps in Splunk Enterprise Security.
Within Splunk SOAR, you cannot edit apps that were configured in Enterprise Security and have the on es poll label. You can delete these apps from within SOAR, in case there is an issue and you need to start over.
See also
For details on apps and assets in Splunk SOAR, see the following articles:
Splunk SOAR (Cloud):
- Add and configure apps and assets to provide actions in Splunk SOAR (Cloud) in the Administer Splunk SOAR (Cloud) documentation.
-
Add tags to objects in Splunk SOAR (Cloud) in Administer Splunk SOAR (Cloud)
Splunk SOAR (On-premises):
- Add and configure apps and assets to provide actions in Splunk SOAR (On-premises) in the Administer Splunk SOAR (On-premises) documentation.
-
Add tags to objects in Splunk SOAR (On-premises) in Administer Splunk SOAR (On-premises)